Security
Enterprise-grade security, built in from day one
Your analytics data is sensitive. Here is exactly how we protect it at every layer.
Data Storage
- All data stored in Neon PostgreSQL, hosted on SOC 2 Type II certified infrastructure (Neon, Vercel). ClimbPast is not itself SOC 2 certified.
- Hosted on AWS infrastructure
- Data encrypted at rest and in transit (TLS 1.2+)
Authentication
- Magic link email authentication (no passwords stored)
- Session tokens with automatic expiry
- Role-based access control (owner, editor, viewer)
Google Integration
- OAuth 2.0 with minimal scopes: read-only for Analytics and Search Console by default. Write access is a separate, explicit opt-in that triggers its own Google consent screen, and nothing writes to your Google data until you grant it.
- Tokens encrypted at rest using AES-256-GCM
- No Google passwords are ever stored
- Users can disconnect Google and all tokens are deleted immediately
Data Access
- Your data is never shared with other workspaces
- AI analysis is scoped to your workspace and runs on isolated infrastructure
- We do not train models on your data
Compliance
- GDPR-ready: data deletion available on request
- No tracking cookies on the app itself (only your own GA4)
- Audit log of all configuration changes
Have security questions?
We are happy to walk through our security posture in detail. Reach out for our full security documentation or to schedule a review.
Contact Security Team